Is key generation algorithm(RSA/DSA) should always same as key exchange algorithm (RSA/DSA) for communication?created pub/priv keys using putty, created .ssh folder and authorized_keys, still not workingHow to use a another private / public keypair (generated by PuTTY) for ssh?Using Plink to script commands to Dell PowerConnect 6224'POSSIBLE BREAK IN ATTEMPT' in /var/log/auth.log when you use private key in putty?Multiple public/private key pairs for the same userConnecting to a remote server using SSH from a MacSSH - Putty Private Key and PassphraseSVN via SSH not working on Windows with Tortoise SVNSSH to WebServer using PuTTYConnection error in bitvise ssh client
A map of non-pathological topology?
If I leave the US through an airport, do I have to return through the same airport?
If there's something that implicates the president why is there then a national security issue? (John Dowd)
Does the Nuka-Cola bottler actually generate nuka cola?
Fermat's statement about the ancients: How serious was he?
Why does this query, missing a FROM clause, not error out?
I've been given a project I can't complete, what should I do?
Write a function that checks if a string starts with or contains something
Can I utilise a baking stone to make crepes?
How to safely destroy (a large quantity of) valid checks?
bash vs. zsh: What are the practical differences?
Does the new finding on "reversing a quantum jump mid-flight" rule out any interpretations of QM?
C++ logging library
Russian word for a male zebra
How do we say "within a kilometer radius spherically"?
Why is Na5 not played in this line of the French Defense, Advance Variation?
Is there a set of positive integers of density 1 which contains no infinite arithmetic progression?
How to prove a 4D vector is a 4-Vector?
Java Servlet & JSP simple login
Does putting salt first make it easier for attacker to bruteforce the hash?
How do i export activities related to an account with a specific recordtype?
Electricity free spaceship
Getting UPS Power from One Room to Another
Ability To Change Root User Password (Vulnerability?)
Is key generation algorithm(RSA/DSA) should always same as key exchange algorithm (RSA/DSA) for communication?
created pub/priv keys using putty, created .ssh folder and authorized_keys, still not workingHow to use a another private / public keypair (generated by PuTTY) for ssh?Using Plink to script commands to Dell PowerConnect 6224'POSSIBLE BREAK IN ATTEMPT' in /var/log/auth.log when you use private key in putty?Multiple public/private key pairs for the same userConnecting to a remote server using SSH from a MacSSH - Putty Private Key and PassphraseSVN via SSH not working on Windows with Tortoise SVNSSH to WebServer using PuTTYConnection error in bitvise ssh client
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
I have generated keys(public and private ) using SSH 2- RSA using putty key generator and configured public key in bitvise SSH server.
when i am trying to connect it with using key exchange : RSA based key exchange it working fine .
however when i am trying to connect it with using key exchange :Diffie-Hellman exchange its not working.
So ,key generation algorithm(RSA/DSA) should always same as key exchange algorithm (RSA/DSA) for communication?
can you anyone help me on this or redirect to links?
Thanks!
sftp putty public-key-encryption
add a comment |
I have generated keys(public and private ) using SSH 2- RSA using putty key generator and configured public key in bitvise SSH server.
when i am trying to connect it with using key exchange : RSA based key exchange it working fine .
however when i am trying to connect it with using key exchange :Diffie-Hellman exchange its not working.
So ,key generation algorithm(RSA/DSA) should always same as key exchange algorithm (RSA/DSA) for communication?
can you anyone help me on this or redirect to links?
Thanks!
sftp putty public-key-encryption
1
The key you generate with puttygen is used for authentication (auth, specifically client auth) NOT keyexchange (kex). In SSH these steps can use the same or different algorithms, but DSA cannot do kex (while DH can only do kex and not auth). Did you try all three DH options? Do you have a packet-level log? That will show what the server offers (though less conveniently than OpenSSHssh -v
does).
– dave_thompson_085
May 26 at 2:20
Yes,kex is happening using DH only.below is the error message we are getting. Fatal: server sent disconnected message type 3(key exchange failed) "FlowSshTransport: no mutually supported host key algorithm.Local list: "ecdsa-sha2-nistp256".Remote list:"ssh-rsa,ssh-dss"."
– user525144
May 27 at 17:58
What version of putty? Your server is offering (only) ecdsa for host key (server auth), and you need putty 0.68 up to support ecdsa (and ed25519) auth. Alternatively, change the server's key(s).
– dave_thompson_085
May 28 at 7:36
Thanks a lot :)
– user525144
May 29 at 21:12
add a comment |
I have generated keys(public and private ) using SSH 2- RSA using putty key generator and configured public key in bitvise SSH server.
when i am trying to connect it with using key exchange : RSA based key exchange it working fine .
however when i am trying to connect it with using key exchange :Diffie-Hellman exchange its not working.
So ,key generation algorithm(RSA/DSA) should always same as key exchange algorithm (RSA/DSA) for communication?
can you anyone help me on this or redirect to links?
Thanks!
sftp putty public-key-encryption
I have generated keys(public and private ) using SSH 2- RSA using putty key generator and configured public key in bitvise SSH server.
when i am trying to connect it with using key exchange : RSA based key exchange it working fine .
however when i am trying to connect it with using key exchange :Diffie-Hellman exchange its not working.
So ,key generation algorithm(RSA/DSA) should always same as key exchange algorithm (RSA/DSA) for communication?
can you anyone help me on this or redirect to links?
Thanks!
sftp putty public-key-encryption
sftp putty public-key-encryption
asked May 25 at 19:58
user525144user525144
1
1
1
The key you generate with puttygen is used for authentication (auth, specifically client auth) NOT keyexchange (kex). In SSH these steps can use the same or different algorithms, but DSA cannot do kex (while DH can only do kex and not auth). Did you try all three DH options? Do you have a packet-level log? That will show what the server offers (though less conveniently than OpenSSHssh -v
does).
– dave_thompson_085
May 26 at 2:20
Yes,kex is happening using DH only.below is the error message we are getting. Fatal: server sent disconnected message type 3(key exchange failed) "FlowSshTransport: no mutually supported host key algorithm.Local list: "ecdsa-sha2-nistp256".Remote list:"ssh-rsa,ssh-dss"."
– user525144
May 27 at 17:58
What version of putty? Your server is offering (only) ecdsa for host key (server auth), and you need putty 0.68 up to support ecdsa (and ed25519) auth. Alternatively, change the server's key(s).
– dave_thompson_085
May 28 at 7:36
Thanks a lot :)
– user525144
May 29 at 21:12
add a comment |
1
The key you generate with puttygen is used for authentication (auth, specifically client auth) NOT keyexchange (kex). In SSH these steps can use the same or different algorithms, but DSA cannot do kex (while DH can only do kex and not auth). Did you try all three DH options? Do you have a packet-level log? That will show what the server offers (though less conveniently than OpenSSHssh -v
does).
– dave_thompson_085
May 26 at 2:20
Yes,kex is happening using DH only.below is the error message we are getting. Fatal: server sent disconnected message type 3(key exchange failed) "FlowSshTransport: no mutually supported host key algorithm.Local list: "ecdsa-sha2-nistp256".Remote list:"ssh-rsa,ssh-dss"."
– user525144
May 27 at 17:58
What version of putty? Your server is offering (only) ecdsa for host key (server auth), and you need putty 0.68 up to support ecdsa (and ed25519) auth. Alternatively, change the server's key(s).
– dave_thompson_085
May 28 at 7:36
Thanks a lot :)
– user525144
May 29 at 21:12
1
1
The key you generate with puttygen is used for authentication (auth, specifically client auth) NOT keyexchange (kex). In SSH these steps can use the same or different algorithms, but DSA cannot do kex (while DH can only do kex and not auth). Did you try all three DH options? Do you have a packet-level log? That will show what the server offers (though less conveniently than OpenSSH
ssh -v
does).– dave_thompson_085
May 26 at 2:20
The key you generate with puttygen is used for authentication (auth, specifically client auth) NOT keyexchange (kex). In SSH these steps can use the same or different algorithms, but DSA cannot do kex (while DH can only do kex and not auth). Did you try all three DH options? Do you have a packet-level log? That will show what the server offers (though less conveniently than OpenSSH
ssh -v
does).– dave_thompson_085
May 26 at 2:20
Yes,kex is happening using DH only.below is the error message we are getting. Fatal: server sent disconnected message type 3(key exchange failed) "FlowSshTransport: no mutually supported host key algorithm.Local list: "ecdsa-sha2-nistp256".Remote list:"ssh-rsa,ssh-dss"."
– user525144
May 27 at 17:58
Yes,kex is happening using DH only.below is the error message we are getting. Fatal: server sent disconnected message type 3(key exchange failed) "FlowSshTransport: no mutually supported host key algorithm.Local list: "ecdsa-sha2-nistp256".Remote list:"ssh-rsa,ssh-dss"."
– user525144
May 27 at 17:58
What version of putty? Your server is offering (only) ecdsa for host key (server auth), and you need putty 0.68 up to support ecdsa (and ed25519) auth. Alternatively, change the server's key(s).
– dave_thompson_085
May 28 at 7:36
What version of putty? Your server is offering (only) ecdsa for host key (server auth), and you need putty 0.68 up to support ecdsa (and ed25519) auth. Alternatively, change the server's key(s).
– dave_thompson_085
May 28 at 7:36
Thanks a lot :)
– user525144
May 29 at 21:12
Thanks a lot :)
– user525144
May 29 at 21:12
add a comment |
0
active
oldest
votes
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f968848%2fis-key-generation-algorithmrsa-dsa-should-always-same-as-key-exchange-algorith%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f968848%2fis-key-generation-algorithmrsa-dsa-should-always-same-as-key-exchange-algorith%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
1
The key you generate with puttygen is used for authentication (auth, specifically client auth) NOT keyexchange (kex). In SSH these steps can use the same or different algorithms, but DSA cannot do kex (while DH can only do kex and not auth). Did you try all three DH options? Do you have a packet-level log? That will show what the server offers (though less conveniently than OpenSSH
ssh -v
does).– dave_thompson_085
May 26 at 2:20
Yes,kex is happening using DH only.below is the error message we are getting. Fatal: server sent disconnected message type 3(key exchange failed) "FlowSshTransport: no mutually supported host key algorithm.Local list: "ecdsa-sha2-nistp256".Remote list:"ssh-rsa,ssh-dss"."
– user525144
May 27 at 17:58
What version of putty? Your server is offering (only) ecdsa for host key (server auth), and you need putty 0.68 up to support ecdsa (and ed25519) auth. Alternatively, change the server's key(s).
– dave_thompson_085
May 28 at 7:36
Thanks a lot :)
– user525144
May 29 at 21:12